PT-2023-25560 · Unknown · Hospital Management System

CVE-2023-36375

·

Publicado

2023-07-10

·

Atualizado

2025-11-11

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hostel Management System version 2.1
Description The issue allows an attacker to execute arbitrary code through a crafted payload to parameters such as Guardian name, Guardian relation, complimentary address, city, permanent address, and city in the Book Hostel & Room Details page.
Recommendations For Hostel Management System version 2.1, consider restricting access to the Book Hostel & Room Details page until a fix is available, and avoid using the parameters Guardian name, Guardian relation, complimentary address, city, permanent address, and city in this page to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-36375

Produtos afetados

Hospital Management System